Direct answer and scope
For a memorial QR code on a headstone or cemetery marker, evaluate the hosted destination rather than treating the physical code as evidence of website continuity. Request separate documentation for the account holder, domain control, renewal terms, export process, privacy terms, guest permissions, and closure plan. A blank field is unresolved rather than proof that a feature, right, or safeguard exists.
Separate access to the live memorial from possession of exported files. The Library of Congress recommends identifying important web content, exporting selected information, preserving metadata such as the site name or creation date, and organizing the resulting files. It also recommends keeping copies in different locations and checking periodically that they remain readable. Those steps do not establish that a particular service offers a complete export or can restore one.
How to use official guidance and written records
For every decision point, record the document requested, the official guidance relevant to the question, the vendor term that remains unresolved, an independent fallback record, and the date of review. Preserve the vendor's written response or contract language without converting silence into a positive answer.
Use each authority for its stated purpose. Federal Trade Commission business guidance supplies questions about data inventory, minimization, safeguards, disposal, incident planning, data movement, recipients, and outside service providers. Library of Congress guidance supports questions about exports, metadata, organization, multiple copies, and readability checks. California privacy guidance addresses covered businesses and applicable consumer rights; it does not establish that any particular memorial vendor is covered.
Decision framework
For account and domain control, request records naming the account holder and the person or entity responsible for the domain. Ask how an authorized change is documented, what happens when the named administrator can no longer act, and whether the written terms address transfer to a successor. Account access, domain control, redirects, and succession remain separate unresolved terms unless current primary documentation addresses each one.
For content export, request a description or sample showing what the export contains, which metadata accompanies it, and whether the files are independently readable. Ask whether photographs, text, dates, captions, guest contributions, and account information are included or omitted, but do not assume any category is available. Record the format without predicting how long it will remain readable. Keep independent copies in different locations and test the saved files periodically.
For privacy and guest permissions, ask who may view, submit, edit, approve, or remove content under the current terms. Ask where account, photograph, memorial, visitor, and support data flow, which outside service providers participate, why each data category is used, and what retention basis is stated. Locate the current privacy-request method and written deletion, retention, and correction terms when California law applies. These questions do not determine CCPA coverage or certify a vendor's practices.
For fees, renewal, closure, and succession, request the complete written charging and renewal terms without estimating an amount. Ask which payments recur, what event triggers renewal, who receives notices, and what the current terms say about cancellation or nonrenewal. For closure, request written provisions addressing advance notice, export, account transfer, domain responsibility, data disposal, and a successor administrator. None of those capabilities should be assumed when current documentation is absent.
Evidence limits and unresolved questions
No current vendor-specific documentation has been validated for identity, products, account control, domain operation, export, file formats, backup, restoration, privacy practices, succession, prices, availability, reviews, ratings, or turnaround. Vendor-specific entries therefore remain unknown. The official materials support a method for requesting evidence, not a conclusion about a particular platform.
The authorities also address different subjects. California privacy guidance describes rights and business duties when the CCPA applies. Federal Trade Commission guidance organizes business data-security planning. Library of Congress guidance concerns personal web archiving. These sources do not create one combined legal, technical, or continuity standard, and they do not establish website operation, long-term link function, export completeness, or service survival.
Checklist questions
The checklist addresses where to obtain a cemetery memorial QR code, how to assess an online memorial website, which account and export records to request, and when California privacy rights apply. Vendor-specific answers remain unresolved, while the official guidance supports documentary questions about privacy, data handling, exports, independent copies, and readability checks.
Evidence behind this page
Each point below is restricted to what the cited primary source supports. Administrative listing status is not a quality endorsement.
| Evidence | Supported point | Scope and limitation |
|---|---|---|
| Evidence 1 | Include a California-scoped question asking a potentially covered vendor where commission, account, photograph, memorial, visitor, and support data flow. | Do not assume that a vendor is subject to the CCPA, that a file or portrait is personal information, or that a particular request must be granted. |
| Evidence 2 | Prompt a California consumer to locate the vendor's current privacy request method and written deletion and retention terms when the law applies. | Do not promise deletion, determine an exception, delete data, submit a request, or state that a vendor or memorial record is covered. |
| Evidence 3 | Include a California-scoped question about the current correction route for account or profile data when applicable. | Do not promise correction, classify portrait likeness or memorial content as inaccurate personal information, or determine that the right applies. |
| Evidence 4 | Ask an applicable business to state the purpose and retention basis for each data category used in a portrait or hosted memorial service. | Do not evaluate necessity or proportionality, certify a privacy practice, or apply the rule to a business whose status has not been verified. |
| Evidence 5 | Turn those headings into vendor questions about data inventory, minimization, safeguards, disposal, and incident response. | Do not certify security, privacy, compliance, breach readiness, encryption, deletion, or the adequacy of any vendor control. |
| Evidence 6 | Include questions about processors, hosting, support, export, backup, and disposal without naming or assuming any service provider. | Do not invent a platform architecture, subprocessors, storage location, access control, cross-border transfer, encryption state, or data-flow answer. |
| Evidence 7 | Ask whether a hosted memorial provides an independently readable export, what the export contains, and which metadata accompanies it. | Do not claim that a vendor offers export, that a browser-saved page is complete, that an export preserves functionality, or that a format will remain readable. |
| Evidence 8 | Separate live memorial availability from possession of independent exported copies and from testing those copies. | Do not promise website uptime, domain renewal, redirect continuity, service survival, full export, restore capability, or long-term link operation. |
| Evidence 9 | Publish official method guidance and vendor-question fields only, leaving vendor-specific values unknown until a separate primary-evidence manifest passes review. | Do not name, list, rank, recommend, contact, quote, compare, review, or imply a feature or capability of any vendor or platform. |
Questions people ask
Where can I find QR codes for cemetery memorials?
The current record contains no validated vendor, product, feature, price, or availability information, so a specific source remains unresolved. For any candidate, request written evidence covering the QR destination, account and domain control, renewal terms, export, privacy practices, guest permissions, and closure arrangements. Do not treat a product listing or an unanswered field as evidence of those terms.
How should I evaluate an online memorial website?
Compare current written evidence for account and domain control, independently readable export, privacy and guest permissions, fees and renewal, and closure or succession. Keep live website access separate from possession of exported copies. No vendor-specific documentation supports a ranking or recommendation, so unresolved terms should remain marked as unknown.
Which account and export evidence should be requested?
Request records naming the account holder and domain controller, the process for authorized changes, and any succession or transfer terms. For export, request a description or sample showing included content, omitted content, file formats, and accompanying metadata. Ask whether the result is independently readable, then maintain copies in different locations and periodically check readability without assuming restoration is available.
When do California privacy rights apply to a business?
The California Attorney General describes rights to know, delete subject to exceptions, and correct personal information when a business is subject to the CCPA. The California Privacy Protection Agency describes purpose-limitation and data-minimization duties for businesses subject to that law. Whether a particular memorial vendor is covered remains unresolved. When applicable, locate its current privacy-request method and written deletion, retention, and correction terms.
Primary sources
- California Attorney General — California Consumer Privacy Act Verified 2026-08-26
- California Privacy Protection Agency — Frequently Asked Questions Verified 2026-08-26
- Federal Trade Commission — Protecting Personal Information: A Guide for Business Verified 2026-08-26
- Library of Congress — Keeping Personal Websites, Blogs and Social Media Verified 2026-08-26
- Memorial Portrait and Digital Continuity Desk validated source and checklist methodology Verified 2026-08-26